Certified Data Privacy Solutions Engineer (CDPSE) — Question 211
Which of the following MUST be included in a contract with a vendor that will be processing personal data?
Answer options
- A. A clause to hash all data that is processed or stored by the vendor
- B. A clause to prohibit the vendor from sending data to third parties
- C. A clause to report breaches in a timely manner to the organization
- D. A clause to require the vendor to comply with industry best practices
Correct answer: C
Explanation
The correct answer, C, is crucial as it ensures the organization is promptly informed of any data breaches, allowing for quick mitigation of risks. Options A, B, and D, while important, do not address the immediate need for breach notification, which is a critical requirement in data protection agreements.